📦 Aim

by Aimstack

🔍 What is Aim?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8769

CRITICAL CVSS 9.1 Mar 20, 2025

This vulnerability allows attackers to delete arbitrary files on systems running the aimhubio/aim tracking server. The flaw exists in the LockManager.release_locks function where user-controlled input...

CVE-2024-7760

CRITICAL CVSS 9.6 Mar 20, 2025

Aim version 3.22.0 has overly permissive CORS settings that allow cross-origin requests from any domain, enabling CSRF attacks on all tracking server endpoints. This vulnerability can be chained with ...

CVE-2024-6829

CRITICAL CVSS 9.1 Mar 20, 2025

This vulnerability in aimhubio/aim allows attackers to exploit insecure tarfile extraction to write arbitrary files to arbitrary locations on the server. By controlling repo.path and run_hash paramete...

CVE-2024-6396

CRITICAL CVSS 9.8 Jul 12, 2024

This vulnerability in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the server and exfiltrate arbitrary data by manipulating the `run_hash` and `repo.path` parameters. I...

CVE-2025-0189

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability allows attackers to cause denial of service in aimhubio/aim tracking servers by sending oversized websocket messages containing large images. The server becomes unresponsive while p...

CVE-2025-0190

HIGH CVSS 7.5 Mar 20, 2025

This CVE describes a denial of service vulnerability in aimhubio/aim version 3.25.0 where an attacker can make the web server unresponsive by tracking numerous Text objects and querying them simultane...

CVE-2024-8061

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in aimhubio/aim version 3.23.0 allows denial of service attacks due to missing timeout configurations in external server communication methods. When the tracking server requests dat...

CVE-2024-6851

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability allows arbitrary file deletion on systems running the aim tracking server. An attacker can craft a glob-pattern to delete files outside the intended directory, potentially causing d...

CVE-2024-12778

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability allows attackers to cause denial of service (DoS) by making API requests for large numbers of tracked metrics simultaneously. The Aim web server becomes unresponsive due to excessiv...

CVE-2024-2196

HIGH CVSS 8.8 Apr 10, 2024

This CSRF vulnerability in aimhubio/aim allows attackers to trick authenticated users into executing unauthorized actions like deleting runs, updating data, and stealing log records and notes. It affe...

CVE-2021-43775

HIGH CVSS 8.6 Nov 23, 2021

CVE-2021-43775 is a path traversal vulnerability in Aim, an open-source machine learning experiment tracking tool. Attackers can use directory traversal sequences like '../' to access arbitrary files ...

CVE-2025-5321

MEDIUM CVSS 6.3 May 29, 2025

This critical vulnerability in aimhubio aim allows remote attackers to execute arbitrary code through improper input validation in the RestrictedPythonQuery function. Attackers can gain elevated privi...

CVE-2024-8101

MEDIUM CVSS 6.1 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in aimhubio/aim version 3.23.0 allows attackers to inject malicious HTML/JavaScript during the training process. When users view tracked texts in the ...

CVE-2024-6483

MEDIUM CVSS 5.3 Mar 20, 2025

This vulnerability allows attackers to delete arbitrary files or directories on systems running aimhubio/aim version 3.19.3 through path traversal in the runs/delete-batch endpoint. Attackers can expl...

CVE-2024-12777

MEDIUM CVSS 5.9 Mar 20, 2025

This vulnerability in aimhubio/aim version 3.25.0 allows attackers to cause denial of service by exploiting the sshfs-client's lack of timeout settings. The single-threaded tracking server can be made...

CVE-2024-6578

MEDIUM CVSS 5.4 Jul 29, 2024

A stored cross-site scripting (XSS) vulnerability in aimhubio/aim version 3.19.3 allows attackers to inject malicious scripts into terminal output logs. When users view the logs-tab, these scripts exe...